Getting Data In

How can I monitor a file when it changes?

New Member

There is a only one file named change.log whose name won't be changed. When my environment changes, I always take this log and append in change.log by script, but Splunk always indexes the new records which I append. How can I get splunk to index the whole content every time change.log updates?

Tags (3)
0 Karma


You can use crcSalt inside inputs.conf


crcSalt = <SOURCE>